Terabytes of credentials leaked in massive supply-chain attack



The firm advised all those affected to perform “aggressive credential revocation,” assume any secret accessible to the LiteLLM environment is compromised, invalidate and rotate all cloud keys, Kubernetes service account tokens, and GitLab/GitHub PATs, and audit logging and egress filtering.

As a cautionary tale, CloudSEK said that Trivy developers rotated, but failed to fully revoke an automation token over a 20-day window. The lapse gave the attackers a nearly three-week period to force-push malicious code to third-party builds that used the vulnerability scanner. As Beaumont observed, organizations’ rush to integrate AI into their software delivery systems has also greatly contributed to the scale of the damage.

Update:There are already signs that some of the affected organizations aren’t taking the disclosure with the seriousness warranted. After this post went live, Beaumont reported:

These creds date from about March. One of the orgs impacted told me they’d rotated them all and it’s a nothingburger, so I looked at their responsible disclosure policy, it allows trying creds, so I tried them all. Almost every one worked. Submitted report. One of the biggest US techcos.

Ultimately, the new revelations concerning the LiteLLM supply-chain attack underscore the growing threat of such campaigns and hence the importance of maintaining vigilance around the use of open source software that, when infected, can spread rapidly across the Internet.

“The key takeaway is how supply chains have evolved to make a single upstream breach affect thousands of companies simultaneously,” Alon Gal, co-founder and chief technology officer of Hudson Rock, wrote in an email. “A window of roughly 40 minutes in which the LiteLLM dependency was hacked led to over 430,000 instances in which millions of secrets were harvested. This magnitude pushes us into a completely new world regarding the type of response required from the cybersecurity industry.”

Post updated to add image.



Source link

  • Related Posts

    The Best Photos of the Big August Solar Eclipse

    Regions such as Galicia, Asturias, Castile and León, Madrid, Aragon, Catalonia, the Valencian Community, and the Balearic Islands experienced the path of totality, while the rest of the country saw…

    Some Claude users are mad that Anthropic’s new watermarks will catch them using it at their jobs, classes

    Anthropic recently made the decision to watermark Claude’s outputs — inserting invisible code into the chatbot’s editorial text that marks it as AI-generated. Anthropic rolled out this new policy to…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Rural family’s hunt for Sask. hospital bed ends with $1,300 ambulance bill

    Rural family’s hunt for Sask. hospital bed ends with $1,300 ambulance bill

    Xbox Gamers Can Play Co-Op RPG Sunderfolk for a Limited Time

    Xbox Gamers Can Play Co-Op RPG Sunderfolk for a Limited Time

    End-of-summer sales: The best deals to shop now – National

    End-of-summer sales: The best deals to shop now – National

    The Best Photos of the Big August Solar Eclipse

    The Best Photos of the Big August Solar Eclipse

    Earn an offer as high as 175,000 points on the Amex Platinum

    Earn an offer as high as 175,000 points on the Amex Platinum

    Bountiful